Cybersecurity Researcher Released VMware Exploit Code

A proof of concept published on GitHub targets a critical integer overflow flaw in VMware Workstation and Fusion.

Updated on Oct. 8, 2026 in Cybersecurity

Isometric editorial illustration of stacked server rack components in muted teal, cream, and oxblood, representing international virtualization infrastructure.
A security researcher has published proof-of-concept code for a critical integer overflow vulnerability affecting VMware Workstation and Fusion virtual network adapters. AI Illustration. Upload story photo >

Live Poll

Do you prioritize installing manual software security updates as soon as they become available?

Security researcher 0xCyberstan has released a proof of concept for vulnerability CVE-2026-59346, which triggers a crash in the vmware-vmx host process. The exploit targets a critical integer overflow in the VMXNET3 virtual network adapter.

Why it matters

The flaw allows a malicious actor with administrative access inside a guest virtual machine to power off the host software. Because no workaround currently exists, patching the software is the only effective defense.

The vulnerability involves a 32-bit multiplication of segment count and required space within the TCP Segmentation Offload path. This calculation fails to validate results, leading to an overflow.

The players

0xCyberstan

This is the security researcher who publicly released the proof of concept for the critical vulnerability.

Broadcom

This is the technology company that maintains the VMware virtualization suite and issued the patches.

Zero Day Initiative

This is a security research organization that specializes in identifying and disclosing software vulnerabilities.

The details

The proof of concept operates as a Linux kernel module that bypasses standard guest driver handling by writing network transmit descriptors directly. This exploit successfully triggers a segmentation fault, forcing a shutdown of the affected virtual machine.

Timeline

  1. September 3, 2026: Broadcom released security patches for affected software.

  2. September 9, 2026: The Zero Day Initiative published its security advisory.

  3. October 8, 2026: The security exploit was publicly documented.

The Tech Race

This incident highlights the ongoing security challenges inherent in complex virtual network hardware emulation. As virtualization platforms expand, the attack surface within adapters like the VMXNET3 remains a primary focus for both researchers and malicious actors.

Users of VMware Workstation and Fusion versions 25H2 and 26H1 should ensure their software is updated to the latest version. Failure to patch leaves virtualized environments vulnerable to crashes initiated by guests with administrative access.

The takeaway

Maintaining up-to-date virtualization software is the most critical step for mitigating risks from disclosed exploits. Users should prioritize applying official patches immediately when vendors confirm an integer overflow or similar memory-based flaw.

Further reading

For more information on defensive measures, visit the Cybersecurity section.

Live Poll

Do you prioritize installing manual software security updates as soon as they become available?